Linux Backdoors Hide as Email Traffic on Telecom and Network Appliances
Rapid7 published research on October 2 describing Linux backdoors used against telecom and network-edge appliances in South Korea and Taiwan. The malware includes a new BPFDoor variant, a BPF Rekoobe build, and a dropper plus six builds of an implant Rapid7 calls AVERAT. Each is designed to blend in, by disguising its traffic as email and naming its processes after legitimate services on the compromised device.
AVERAT connects out on TCP port 25 and uses the standard email protocol, then requests encryption before starting its own encrypted session. On a mail security gateway, where outbound mail is the device's normal job, Rapid7 said this looks the same as legitimate activity in flow records. The implant checks in roughly every 10 to 12 minutes and supports file transfers, ending processes, up to ten concurrent shell sessions and proxy or port-forwarding channels. The Rekoobe sample and one BPFDoor variant impersonate components of a South Korean anti-spam product, and Rapid7 said firewall rules allowing mail relay could let a trigger packet reach the implant. Another BPFDoor controller wraps its trigger in HTTPS requests, which may help it pass edge proxies and evade deep-packet inspection.
Three AVERAT builds report to addresses on compromised third-party devices in Taiwan: a Synology NAS, an obsolete small-business appliance and a Dahua video recorder. Rapid7 believes the operators installed an identical VPN service on each. The relays match a CISA advisory profile for China-nexus covert networks, but Rapid7 found no overlap with any named network and said attribution is ongoing.